Patent ReferencesCryptographic file security for single domain networks Protected software access control apparatus and method Method for utilizing an encrypted key as a key identifier in a data packet in a computer network System and method for secure initial program load for diskless workstations Patent #: 5349643 InventorsApplicationNo. 235578 filed on 04/29/1994US Classes:713/155, Central trusted authority provides computer authentication380/277KEY MANAGEMENTExaminersPrimary: Cain, DavidAttorney, Agent or FirmInternational ClassH04K 001/00AbstractA computing system is described having an automated management system for managing keys to encrypt and decrypt stored data on the computing system. The computing system has an authentication server; a key client; a key generator; a key server; a key database; and an encrypted data file memory. The authentication server authenticates the user and in response to the user accessing the computing system the authentication server provides the user with a ticket validating the user. The key client of a creating user when creating a data file invokes the generator to generate a key corresponding to the data file. The key is provided to the key server and the key client uses the key to encrypt the data file which is stored in the encrypted data file memory. The key client of an accessing user sends its ticket and data file identification data to the key server. The key server checks the ticket and sends the key corresponding to the data file to the key client of the accessing user. The key client of the accessing user uses the key to decrypt the encrypted data file. The stored data can further include a header containing the key and owner and permitted user identification data. The ticket can contain a key to encrypt messages sent between the client server and key client.Other References
| |